Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.0-debian-dev, 8.0-debian13-dev, 8.0-dev, 8.0.32-debian-dev, 8.0.32-debian13-dev, 8.0.32-dev

Index digest:

sha256:ae0225e849fa513ffee9019040949262642c271e89c06cca9dcba2bfe594397c

Manifest digest:

sha256:d7559a17e393a735a61cf661688dec0d318dd608b81c956b35fd9566f637e73a

Size

191.12 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:cfb45e35425be036af1b93c1d20bd159bfe548d7163f3044160d4f12aa7b0eb9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:bc983bfea5e0781c7a422fa851edc68b63735f5564346b13cb62edf9941abe36
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:ca86568b402f391d16d18636819f6bb77cc063277c2cff7082c5d7f17d7d3bf6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:b5aac7582beb229f5682a96c161cb4e0fde7f17fe9a8f1d80b6bb0a6d2ca1b90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:78f180d101bde775c3c59ae46f8fe0242870f8ebb744f94d62ea327cb4e3a662
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:3e6d4812dd5f1c03b9d2bc1fc88318a7dffe7508ee1dd89a89103212fe6944c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:41d7de53cfaafc97888acb4a752d5f6599812c56b2148a2c26389a64bdd10be1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:61b3aa0469dca2cd0427107a23e82852cb77eb401f197463dbd37dfcf303f036
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:c7f529f15cebfff62e3c9d5c516d27c118936a6bb44447b4260626b70d304914
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:806bb6b04b1e00f6eb71eae8746c7ee05444834a80ad8eb4efc28f84da700de7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:ef42bcfc1b86625bf96652e1326cd99759d2966dc424351cdaf9b7cbed45fc37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:dc577b1f4aa3cdf1dfb75b724b469a30fae7aeb6f2d42a5725b748b82ce289ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:412244eb81bb6cabfc131f69d6037a8236ea2e795ccee19bbf6b28d5ec4487e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:a6cafcaf04fdb633cc895ae05c4455106da78adcda6259c1616e154cc81915bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:4e175586d45a22a96ee6478df24aa0b3143c311926c86a6afe8b0ad8f12dae57